
A working DoD 5015.02 compliance program for defense contractors: run a gap assessment, select a records system after the JITC certification program ended in 2025, build file plans and NARA-approved disposition, stand up a defensible audit trail, and handle CUI under DFARS 252.204-7012, NIST SP 800-171, and CMMC.
Guide briefing
DoD 5015.02 compliance means a contractor's records system meets the standard's minimum functional requirements — to identify, mark, store, and dispose of electronic records — while protecting Controlled Unclassified Information under DFARS 252.204-7012, the 110 controls of NIST SP 800-171, and CMMC. The DoD cancelled the 5015.02-STD on July 2, 2025, but its functional baseline remains the working reference.
More from the Compliance & Regulations category.
Next step
Share the framework, records condition, workflow, capacity issue, or implementation risk. Reynolds routes it to the discipline that owns the work — from Emmaus, with same-day response.
Need help applying this guide?
Talk to a specialistFor a defense contractor, DoD 5015.02 compliance is often misread as a purchase: buy a certified system and the obligation is met. It is not. DoD 5015.02 is two things. The first is DoD 5015.02-STD, a design-criteria standard that sets the minimum functional requirements a records system must meet to identify, mark, store, and dispose of electronic records. The second is DoD Instruction 5015.02, which sets records-management policy and responsibilities. The standard defines what a system must be able to do; it does not define how a product delivers those capabilities or how your organization runs its program. That gap — between owning capable software and operating a defensible program — is where contractor compliance is decided.
The ground shifted in 2025. As of July 2, 2025, the DoD cancelled the 5015.02-STD and superseded it with DoD Manual 8180.01, 'Information Technology Planning for Electronic Records Management,' and the Joint Interoperability Test Command (JITC) terminated the records-management test program that had certified products against the standard. The functional baseline endures as the working reference for contracts and commercial records platforms; the formal DoD certification regime contractors once relied on does not.
This guide builds the program step by step for records and compliance leads: a gap assessment, system selection in the post-certification environment, file plans tied to National Archives disposition authority, a defensible audit trail, and the Controlled Unclassified Information (CUI) stack — DFARS 252.204-7012, the 110 security requirements of NIST SP 800-171, and the Cybersecurity Maturity Model Certification (CMMC) — that now sits alongside records management. It closes with a readiness checklist and the Pennsylvania context Reynolds Business Systems works in.
DoD 5015.02-STD sets minimum functional requirements — the design criteria a system needs to identify, mark, store, and dispose of electronic records. It deliberately stops there: the standard does not specify how a product implements those functions, nor how an agency or contractor runs its records program. Above the standard sits the policy layer. DoD Instruction 5015.02, 'DoD Records Management Program,' was issued February 24, 2015 (Incorporating Change 1) and assigns the policy and responsibilities that govern records management across the Department.
The practical reading for a compliance lead is clean: the Instruction is the policy you align to, the standard is the functional benchmark your system is measured against, and the program — the people, procedures, and documentation you operate daily — is the part no purchase order can satisfy for you. A contractor can own a platform that meets every functional criterion and still fail, because records were never declared, retention never scheduled, disposition never documented, or CUI never adequately protected. Compliance is a program, not a product, and the steps below build that program around the software.
Any 2026-era program has to start by acknowledging that the formal certification path has closed. As of July 2, 2025, the DoD 5015.02-STD was cancelled and superseded by DoD Manual 8180.01. At the same time, the JITC Records Management test program — which certified records management applications against the 5015.02-STD — was terminated, a step that invalidated current support agreements with JITC RM customers. No DoD body is issuing new conformance certifications against the standard. The proof mechanism has changed: instead of a JITC certificate, a contractor now demonstrates conformance through its own evidence — capability mapping, configuration documentation, and a program that visibly applies the standard's functions.
The standard reached this point over nearly three decades. The Department first released the Design Criteria Standard for Electronic Records Management Applications, DOD 5015.2-STD, in November 1997, revised it in June 2002 to add classified markings, access control, declassification, and downgrading, and signed the current functional version, DoD 5015.02-STD, on April 25, 2007 — the design criteria referenced in DoDI 5015.02. The 2015 Instruction set the surrounding policy; the 2025 cancellation moved the framework toward DoD Manual 8180.01.
| Date | Milestone | What it changed |
|---|---|---|
| November 1997 | DOD 5015.2-STD first released | Established design criteria for electronic records management applications |
| June 2002 | Standard revised | Added classified markings, access control, declassification, and downgrading |
| April 25, 2007 | DoD 5015.02-STD signed | Current functional version, referenced by DoD Instruction 5015.02 |
| February 24, 2015 | DoDI 5015.02 issued (Change 1) | Set DoD records-management policy and responsibilities |
| July 2, 2025 | 5015.02-STD cancelled | Superseded by DoD Manual 8180.01; JITC test program terminated |
Strip the standard to its essentials and four functional pillars remain: identify, mark, store, and dispose. Each maps to a concrete program obligation, and the gap assessment in the next section is essentially a check of whether your system and procedures cover all four. Two of these capabilities — classified markings and access control — were added in the 2002 revision, a reminder that the standard has always treated sensitivity marking and controlled access as records-management functions, not afterthoughts.
| Function | What the standard expects | Program implication |
|---|---|---|
| Identify | Capture records and the metadata that make each one findable and authentic | Records are declared and indexed, not left as loose files |
| Mark / categorize | Assign records to a file plan and record categories, with classified markings and access controls | A maintained file plan and role-based access, capabilities added in 2002 |
| Store | Keep records legible, complete, and unaltered for their full retention period | Format and integrity controls spanning the entire retention term |
| Dispose | Apply retention and execute transfer or destruction under an approved authority | Scheduled, documented disposition rather than ad hoc deletion |
Because the standard governs the system's capabilities rather than your operating procedures, conformance is necessary but not sufficient. A system that can mark, categorize, and dispose of records still depends on a program that actually assigns categories, sets retention, and authorizes disposition.
A compliance program starts with an honest inventory. Before selecting tools or writing policy, a contractor needs to know what records it holds, which are federal records created or maintained for the Government, where CUI lives, and how today's systems and procedures measure against the functional baseline and the CUI stack. The assessment turns 'we think we are compliant' into a documented list of what is in place and what is missing.
Run the records gap and the security gap as one exercise. The same CUI documents that drive your NIST SP 800-171 and CMMC obligations are the records your file plan and disposition schedule have to govern. Assessing them separately is how contractors end up with a compliant network and an undocumented records pile, or the reverse.
System selection used to have a shortcut: choose a product on the JITC test register. With that program ended, the shortcut is gone. Selection now rests on demonstrable conformance to the 5015.02 functional criteria plus clean integration with the CUI and disposition obligations the system supports. Historical records show products such as Alfresco's records module passed the former testing process. Build a capability checklist from the current requirements and require the vendor to demonstrate how the configured product meets each item, rather than relying on a retired badge or brochure claim.
Selection is also where the records system meets the security boundary. Because the platform holds CUI, it falls inside the scope of your NIST SP 800-171 controls and your CMMC assessment, so a system that complicates access control, logging, or encryption expands the cybersecurity work in Step 5.
A configured system is inert until a file plan gives it structure, organizing records into categories and assigning each a retention period and a disposition action. The governing rule is unambiguous: under 36 CFR Part 1225, all federal records — including those created or maintained for the Government by a contractor — must be covered by a National Archives-approved disposition authority. You do not invent retention periods; you apply the authority that covers the record.
Format is part of disposition planning, not separate from it. Under OMB Memorandum M-23-07, federal agencies were required to manage all permanent records in an electronic format with appropriate metadata by June 30, 2024 — a standard that flows to contractors creating federal records on the Government's behalf. A file plan that still routes permanent records to paper-only storage is planning for a format the receiving agency is no longer positioned to accept.
Disposition is the action most likely to be questioned after the fact, which is why the audit trail is the backbone of a defensible program. A record's authenticity and a disposition's legitimacy both rest on being able to show who did what, and when. The goal is an evidentiary chain, not just an activity log.
A defensible records program is not one that destroyed nothing it should have kept. It is one that can prove every disposition was eligible, authorized, and documented.
For a defense contractor, records management and cybersecurity are no longer separate disciplines: the records you schedule and dispose of are frequently the same Controlled Unclassified Information your contract obligates you to protect. The CUI Program was established by Executive Order 13556 to standardize how the executive branch handles unclassified information that requires safeguarding, and it is codified at 32 CFR Part 2002, which sets policy for designating, handling, and decontrolling CUI.
The operative contract clause is DFARS 252.204-7012. It requires contractors to implement the security requirements of NIST SP 800-171, to rapidly report cyber incidents to DoD within 72 hours of discovery, and to preserve and protect images of all known affected information systems for at least 90 days from submission of the incident report. The clause must be flowed down in subcontracts for operationally critical support or that involve covered defense information, extending the same safeguarding and reporting duties to subcontractors — a prime cannot satisfy 7012 while its suppliers ignore it. The control set is NIST SP 800-171: 110 security requirements organized into 14 control families. A version nuance matters: Revision 2 was withdrawn on May 14, 2024 and superseded by Revision 3, but the DoD's CMMC program and DFARS 252.204-7012 still reference the 110 requirements of Revision 2, so do not assume the newer revision automatically governs your current contract.
CMMC is the verification layer placed on top, with assessments at three progressive levels keyed to the sensitivity of the Federal Contract Information (FCI) or CUI a contractor handles. Level 1 (Basic Safeguarding of FCI) requires an annual self-assessment and affirmation against the 15 security requirements in FAR clause 52.204-21. Level 2 (Broad Protection of CUI) requires compliance with the 110 NIST SP 800-171 Revision 2 requirements, verified by a self-assessment or an independent C3PAO assessment every three years. Level 3 (protection against advanced persistent threats) adds 24 requirements selected from NIST SP 800-172 and requires an assessment by DCMA's DIBCAC every three years. A CMMC status is valid for three years from the CMMC Status Date, and Plans of Action and Milestones (POA&Ms) are permitted only for a limited set of requirements and must be closed out within 180 days of the Conditional CMMC Status Date. The program is governed by 32 CFR Part 170, whose final rule was published October 15, 2024, with Phase 1 of implementation beginning November 10, 2025 and full implementation phased in over three years.
| Level | Protects | Requirements | Assessment |
|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 15 requirements (FAR 52.204-21) | Annual self-assessment and affirmation |
| Level 2 | Controlled Unclassified Information (CUI) |
Putting the pieces together makes the program concrete. The scenario below uses an illustrative contractor; the requirement counts and deadlines are fixed by the rules and are cited throughout this guide.
A 40-person precision-machining subcontractor in the Lehigh Valley wins a DoD subcontract and begins receiving CUI. Because the prime's contract carries DFARS 252.204-7012, the clause flows down to the shop, which must implement the 110 NIST SP 800-171 requirements. Handling CUI places it at CMMC Level 2, so it must pass a self-assessment or a C3PAO assessment, with the resulting status valid for three years. If an attacker compromises a workstation, the shop has 72 hours to report the incident to DoD and must preserve images of the affected systems for at least 90 days from submission of the report. Any eligible requirement it cannot yet meet may go on a POA&M, but only for a limited set of requirements, and it must be closed within 180 days of the Conditional CMMC Status Date. The 40-person figure is illustrative; the deadlines and requirement counts are set by the rules.
The records side and the security side interlock. The CUI the shop protects under 7012 is the same record series its file plan governs and its disposition schedule eventually retires. Treating 5015.02 and CMMC as unrelated projects means maintaining two inventories of the same documents, reconciled only when an assessor or auditor forces the issue. The table below shows the two tracks side by side.
| Instrument | What it governs | Core obligation |
|---|---|---|
| DoD 5015.02-STD | Records-system functional design criteria | Identify, mark, store, dispose (cancelled July 2, 2025; baseline still referenced) |
| DFARS 252.204-7012 | Safeguarding covered defense information | Implement NIST SP 800-171; report incidents within 72 hours; preserve images 90 days; flow down |
Compliance is a state you maintain, not a milestone you pass. The recurring obligations are predictable: an annual self-assessment and affirmation at CMMC Level 1; a triennial assessment cycle at Levels 2 and 3, since status is valid for three years; continuous execution of the disposition schedule; periodic review of the audit trail; and an eye on the transition toward DoD Manual 8180.01. A program that runs on a calendar — assessments, disposition runs, and POA&M closeouts all scheduled rather than improvised — is far harder to knock out of compliance than one that reacts to deadlines. Most failures are not exotic; they cluster around a handful of avoidable mistakes, each mapping to a specific obligation above.
Treating a former JITC test result as a current DoD endorsement is a serious procurement trap. The defensible posture is to show conformance to current requirements through configuration and program evidence, not through a product-test badge from a program that ended.
The checklist below condenses the program into a sequence a records or compliance lead can run, review annually, and hand to an assessor.
These obligations apply to contractors nationwide, but the work of meeting them is local. Reynolds Business Systems is a family-owned firm based in Emmaus, Pennsylvania, serving the Lehigh Valley — Allentown, Bethlehem, and Easton — and the wider Mid-Atlantic for more than 55 years. Its work sits on the records side of this program: digitizing paper into managed electronic form, building file plans and retrieval systems, and applying disposition discipline so destruction and transfer are scheduled, authorized, and documented. Reynolds is a Laserfiche Certified Partner and a document-management specialist, not a CMMC assessor or certifying body; the cybersecurity assessment belongs to your security team and an authorized C3PAO. The role of a records partner is to make the records half of DoD 5015.02 compliance — declaration, retention, disposition, and audit-ready documentation — dependable rather than improvised.
No. As of July 2, 2025, the DoD cancelled the 5015.02-STD and superseded it with DoD Manual 8180.01, 'Information Technology Planning for Electronic Records Management,' and the JITC records-management test program that certified products against the standard was terminated. The functional baseline the standard defined is still widely referenced in contracts and records platforms, but it is no longer a current standard with an active DoD certification program behind it.
The Joint Interoperability Test Command (JITC) ran the Records Management program that tested applications against DoD 5015.02-STD. That program ended, and JITC's notice said the change invalidated existing support agreements with its records-management customers. No DoD body now tests new products under the cancelled standard; contractors demonstrate current conformance through configuration and program evidence mapped to DoDI 5015.02 and DoDM 8180.01.
NIST SP 800-171 contains 110 security requirements, organized into 14 control families. Revision 2 was withdrawn on May 14, 2024 and superseded by Revision 3, but the DoD's CMMC program and DFARS 252.204-7012 continue to reference the 110 requirements of Revision 2. Contractors should confirm which revision their specific contract invokes rather than assuming the newest version applies.
CMMC has three progressive levels keyed to the sensitivity of the information handled. Level 1 covers Federal Contract Information with 15 requirements from FAR 52.204-21 and an annual self-assessment. Level 2 covers CUI with the 110 NIST SP 800-171 Revision 2 requirements, verified by a self-assessment or an independent C3PAO assessment every three years. Level 3 adds 24 requirements from NIST SP 800-172 and is assessed by DCMA's DIBCAC every three years.
Yes. DFARS 252.204-7012 must be flowed down in subcontracts for operationally critical support or that involve covered defense information, extending the same CUI safeguarding and incident-reporting duties to subcontractors. The clause also requires reporting cyber incidents to DoD within 72 hours of discovery and preserving images of affected systems for at least 90 days from submission of the report.
The CMMC Program is governed by 32 CFR Part 170, whose final rule was published October 15, 2024. Phase 1 of implementation began November 10, 2025, initially focused on Level 1 and Level 2 self-assessments, with full implementation phased in over three years. A CMMC status, once achieved, is valid for three years from the CMMC Status Date.
Controlled Unclassified Information is unclassified information that nonetheless requires safeguarding or dissemination control. The CUI Program was established by Executive Order 13556 to standardize how the executive branch handles such information, and it is codified at 32 CFR Part 2002, which sets policy for designating, handling, and decontrolling CUI across the executive branch.
The foundational statute is the Federal Records Act (44 U.S.C.), which establishes how federal records are created, managed, and dispositioned. For contractors, the operative regulation is 36 CFR Part 1225: federal records — including those created or maintained for the Government by a contractor — must be covered by a National Archives-approved agency disposition authority. Retention periods are set by that authority, not chosen independently.
DoD 5015.02-STD sets minimum functional requirements built around four capabilities: identify (capture records and their metadata), mark or categorize (assign records to a file plan and apply classified markings and access controls), store (keep records legible and unaltered through retention), and dispose (apply retention and execute transfer or destruction under an approved authority). The standard governs what the system must do, not how an organization runs its program.
DoD records-management policy is set through DoD Instruction 5015.02, issued February 24, 2015, with the functional design criteria historically supplied by the 5015.02-STD. The framework is now transitioning to DoD Manual 8180.01 following the standard's cancellation on July 2, 2025. Running through all of it is the broader federal push toward electronic recordkeeping: under OMB Memorandum M-23-07, permanent records were to be managed electronically with metadata by June 30, 2024.
No. As of July 2, 2025, the DoD cancelled the 5015.02-STD and superseded it with DoD Manual 8180.01, 'Information Technology Planning for Electronic Records Management,' and the JITC records-management test program that certified products against the standard was terminated. The functional baseline the standard defined is still widely referenced in contracts and records platforms, but it is no longer a current standard with an active DoD certification program behind it.
The Joint Interoperability Test Command (JITC) ran the Records Management program that tested applications against DoD 5015.02-STD. That program ended, and JITC's notice said the change invalidated existing support agreements with its records-management customers. No DoD body now tests new products under the cancelled standard; contractors demonstrate current conformance through configuration and program evidence mapped to DoDI 5015.02 and DoDM 8180.01.
NIST SP 800-171 contains 110 security requirements, organized into 14 control families. Revision 2 was withdrawn on May 14, 2024 and superseded by Revision 3, but the DoD's CMMC program and DFARS 252.204-7012 continue to reference the 110 requirements of Revision 2. Contractors should confirm which revision their specific contract invokes rather than assuming the newest version applies.
CMMC has three progressive levels keyed to the sensitivity of the information handled. Level 1 covers Federal Contract Information with 15 requirements from FAR 52.204-21 and an annual self-assessment. Level 2 covers CUI with the 110 NIST SP 800-171 Revision 2 requirements, verified by a self-assessment or an independent C3PAO assessment every three years. Level 3 adds 24 requirements from NIST SP 800-172 and is assessed by DCMA's DIBCAC every three years.
Yes. DFARS 252.204-7012 must be flowed down in subcontracts for operationally critical support or that involve covered defense information, extending the same CUI safeguarding and incident-reporting duties to subcontractors. The clause also requires reporting cyber incidents to DoD within 72 hours of discovery and preserving images of affected systems for at least 90 days from submission of the report.
The CMMC Program is governed by 32 CFR Part 170, whose final rule was published October 15, 2024. Phase 1 of implementation began November 10, 2025, initially focused on Level 1 and Level 2 self-assessments, with full implementation phased in over three years. A CMMC status, once achieved, is valid for three years from the CMMC Status Date.
Controlled Unclassified Information is unclassified information that nonetheless requires safeguarding or dissemination control. The CUI Program was established by Executive Order 13556 to standardize how the executive branch handles such information, and it is codified at 32 CFR Part 2002, which sets policy for designating, handling, and decontrolling CUI across the executive branch.
The foundational statute is the Federal Records Act (44 U.S.C.), which establishes how federal records are created, managed, and dispositioned. For contractors, the operative regulation is 36 CFR Part 1225: federal records — including those created or maintained for the Government by a contractor — must be covered by a National Archives-approved agency disposition authority. Retention periods are set by that authority, not chosen independently.
DoD 5015.02-STD sets minimum functional requirements built around four capabilities: identify (capture records and their metadata), mark or categorize (assign records to a file plan and apply classified markings and access controls), store (keep records legible and unaltered through retention), and dispose (apply retention and execute transfer or destruction under an approved authority). The standard governs what the system must do, not how an organization runs its program.
DoD records-management policy is set through DoD Instruction 5015.02, issued February 24, 2015, with the functional design criteria historically supplied by the 5015.02-STD. The framework is now transitioning to DoD Manual 8180.01 following the standard's cancellation on July 2, 2025. Running through all of it is the broader federal push toward electronic recordkeeping: under OMB Memorandum M-23-07, permanent records were to be managed electronically with metadata by June 30, 2024.
| 110 NIST SP 800-171 Rev. 2 requirements |
| Self-assessment or C3PAO every three years |
| Level 3 | CUI against advanced persistent threats | Level 2 plus 24 requirements (NIST SP 800-172) | DCMA DIBCAC every three years |
|---|
| NIST SP 800-171 | Protecting CUI in nonfederal systems | 110 security requirements across 14 control families |
|---|
| CMMC (32 CFR Part 170) | Verifying CUI/FCI protection | Three levels; status valid three years; Phase 1 began November 10, 2025 |
|---|
| 36 CFR Part 1225 (NARA) | Federal records disposition | Records made for the Government covered by a NARA-approved disposition authority |
|---|